SSL per domain

Discuss your pilot or production implementation with other Zimbra admins or our engineers.
Post Reply
armitage318
Advanced member
Advanced member
Posts: 98
Joined: Sat Sep 13, 2014 2:01 am

SSL per domain

Post by armitage318 »

Hi,
I am using ZCS Release 8.8.7_GA Open Source Edition.
For example, my ZCS server has hostname "server.compay.com".
I configured a secondary domain (like company2.com) and created several mailboxes.
I need to install a certificate (which I do have already) on company2.com

How can I do this?
Is it necessary to add another IP address?
OS is CentOS 7.

Thank you very mych
User avatar
axslingr
Outstanding Member
Outstanding Member
Posts: 256
Joined: Sat Sep 13, 2014 2:20 am
ZCS/ZD Version: 8.8.15.GA.3869.UBUNTU18.64 UBUNTU18

Re: SSL per domain

Post by axslingr »

Easiest thing to do is have a cert with a CN of your server hostname and a SAN of the secondary domain. Then follow this guide to deploy:

https://wiki.zimbra.com/wiki/Administra ... ficate_CLI

Lance
armitage318
Advanced member
Advanced member
Posts: 98
Joined: Sat Sep 13, 2014 2:01 am

Re: SSL per domain

Post by armitage318 »

axslingr wrote:Easiest thing to do is have a cert with a CN of your server hostname and a SAN of the secondary domain. Then follow this guide to deploy:

https://wiki.zimbra.com/wiki/Administra ... ficate_CLI

Lance
Hi, thank you for your reply.
Is this

https://wiki.zimbra.com/wiki/Multiple_S ... _for_HTTPS

suitable in my case?

Unfortunately, I got a certificate for only a CN.
User avatar
axslingr
Outstanding Member
Outstanding Member
Posts: 256
Joined: Sat Sep 13, 2014 2:20 am
ZCS/ZD Version: 8.8.15.GA.3869.UBUNTU18.64 UBUNTU18

Re: SSL per domain

Post by axslingr »

Hi, thank you for your reply.
Never tried it but it might work.
Unfortunately, I got a certificate for only a CN.
It's usually pretty easy to add a SAN to a cert. Just depends on where you got it.

Lance
armitage318
Advanced member
Advanced member
Posts: 98
Joined: Sat Sep 13, 2014 2:01 am

Re: SSL per domain

Post by armitage318 »

axslingr wrote:
It's usually pretty easy to add a SAN to a cert. Just depends on where you got it.

Lance
I got my cert from GoDaddy.
But it is only valid for 1 CN, I don't think I can add further SAN (I should pay for ad "UCC" certificate, valid for 5 domains)
Post Reply